Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 239

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Pope Leo XIV urges peace in first Easter Mass, skips naming conflicts in Urbi et Orbi
Here are the 3 big things we're watching in the stock market in the week ahead
The PWHL is growing and post-Olympics boom may take women's hockey to the next level
Tell me about barre classes
ICE agents shoot man in California after he 'weaponized' vehicle, DHS says
AWS teams working around the clock to keep Middle East services up after drone strikes, CEO says
Movie: The House by the Cemetery
First ships pass Strait of Hormuz since Trump-Iran ceasefire, but traffic remains low amid confusion
Ray Dalio: Trump-Xi meeting to focus on trade, capital flows
Delta CEO says airline will 'meaningfully' cut growth plans, sees $300 million boost from its refinery